Description
Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.
Affected products
- Microsoft / access2007 – 2007
- Microsoft / Excel2003 – 2003
- Microsoft / Excel2007 – 2007
- Microsoft / frontpage2003 – 2003
- Microsoft / groove2007 – 2007
- Microsoft / infopath2003 – 2003
- Microsoft / infopath2007 – 2007
- Microsoft / office2007 – 2007
- Microsoft / office2007 – 2007
- Microsoft / office_communicator2007 – 2007
- Microsoft / OneNote2003 – 2003
- Microsoft / Outlook2003 – 2003
- Microsoft / Outlook2007 – 2007
- Microsoft / PowerPoint2003 – 2003
- Microsoft / PowerPoint2007 – 2007
- Microsoft / project_professional2007 – 2007
- Microsoft / project_standard2007 – 2007
- Microsoft / publisher2003 – 2003
- Microsoft / publisher2007 – 2007
- Microsoft / sharepoint_designer2007 – 2007
- Microsoft / visio_professional2007 – 2007
- Microsoft / visio_standard2007 – 2007
- Microsoft / windows_live_mail2008 – 2008
References
- VENDOR_ADVISORYhttps://www.cynops.de/advisories/AKLINK-SA-2008-003.txt
- MISChttp://securityreason.com/securityalert/3978
- MISChttp://www.securityfocus.com/archive/1/494101/100/0/threaded
- MISChttp://www.securityfocus.com/bid/28548
- MISChttps://www.klink.name/security/aklink-sa-2008-004-office2007-signatures.txt
- VENDOR_ADVISORYhttps://www.cynops.de/advisories/AKLINK-SA-2008-002.txt
- VENDOR_ADVISORYhttps://www.cynops.de/advisories/AKLINK-SA-2008-004.txt
- MISChttp://www.securitytracker.com/id?1019736
- MISChttp://www.securitytracker.com/id?1019738
- MISChttps://www.klink.name/security/aklink-sa-2008-003-live-mail-smime.txt
- MISChttps://www.klink.name/security/aklink-sa-2008-002-outlook-smime.txt
- MISChttp://www.securitytracker.com/id?1019737
- MISChttps://www.cynops.de/techzone/http_over_x509.html
- MISChttp://www.securityfocus.com/archive/1/493947/100/0/threaded